Sub-processors

Caresoft Systems Private Limited  •  Version: [1.0]  •  Last updated: [DD Month YYYY]

This page lists the third parties Caresoft engages to process customer data, per product. It is referenced by the Master Data Processing Addendum §9 and by every product privacy policy. Subscribe to change notifications at the bottom of this page.

[BEFORE PUBLISHING — REPLACE EVERY BRACKETED PROVIDER NAME WITH THE ACTUAL VENDOR, ITS ENTITY NAME AND ITS LOCATION.]

A sub-processor page with placeholder names is worse than no page, because customers will ask and the gap becomes visible at exactly the wrong moment. The categories and the structure below are correct; the names must be real before this goes live.

Three commitments that apply to every entry on this page:

1. Every sub-processor is engaged under a written contract imposing obligations materially equivalent to those we owe you.
2. Caresoft remains fully liable to you for its sub-processors. "Our vendor did it" is not a defence we will offer.
3. We give 30 days' notice before a new sub-processor begins processing your data, and you may object.

1. What a sub-processor is

Where we process personal data on your behalf, a sub-processor is a third party we engage that also processes that data — a hosting provider, a messaging gateway, a payment processor. Under the Digital Personal Data Protection Act, 2023 and the GDPR where it applies, you are entitled to know who they are.

A vendor is only a sub-processor if it can access your data. A supplier we buy laptops or accounting software from is not.

2. How we choose them

Before engaging any sub-processor we assess: security posture and certifications; where it processes and stores data; its own sub-processing chain; incident history and how it handled incidents; its contractual willingness to accept obligations equivalent to ours; and whether the function can reasonably be performed without it.

The last question is the one that keeps this list short. Every sub-processor is another party holding customer data and another link that can fail. We add one when the function genuinely requires it, not because a tool is convenient.

3. Shared infrastructure

Used across products unless a product schedule says otherwise.

ProviderFunctionData it can accessLocation
[Hosting provider — entity name]Application and database hosting, backupsEncrypted data at rest and in transit for the products it hostsIndia — [region]
[Transactional email provider]System email — account notices, reports, alertsRecipient address and message content[location]
[SMS gateway]OTP and notification SMSMobile number and message textIndia
[WhatsApp Business Solution Provider]WhatsApp messaging where a product uses itMobile number and message text[location]
[Payment gateway]Subscription and customer paymentsPayment details. Card data is held by the gateway, never by CaresoftIndia
[Error monitoring provider]Application error reportingStack traces and technical context. Configured to scrub personal data before transmission[location]

4. By product

Sahi Writing assistant

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, paymentsAccount data
[AI provider]AI-assisted suggestions — only where AI features are enabledThe passage being checked. Contractually prohibited from training on it. Can be disabled entirely per organisation

On-premise deployments have no sub-processors — nothing reaches Caresoft or any third party.

Sloto Scheduling

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, paymentsAccount and booking data
[Video conferencing providers]Meeting links, where the Host connects oneMeeting details. Independent controllers once connected by the Host
[Calendar providers]Free/busy and event creation, where the Host connects oneCalendar data. Google user data handled under Limited Use requirements

Sales Sathi Accounting BI

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, paymentsImported accounting data, account data
[AI provider]Prompt bar dashboards — only where AI is enabledThe prompt and relevant schema and figures. Prohibited from training on it. Can be disabled entirely

Screenify Hospital display and media

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, paymentsContent, schedules, proof of play
[CDN / media delivery]Delivering creative to screensMedia files. No patient or queue data

No audience measurement provider exists, because there is no audience measurement — no cameras, sensors or tracking.

CareHire Healthcare jobs

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, SMSProfiles, applications, messages
[Document storage / virus scanning]Resume and certificate handlingUploaded documents

Employers who receive an application become independent controllers of their copy — they are not sub-processors.

Partners Unite Channel platform

ProviderFunctionReceives
Shared infrastructure (§3)Hosting, email, SMS, paymentsPartner and user data, opportunities

5. Health data products

For products processing health data, no sub-processor outside India is engaged for that data without the customer's prior written consent.

This applies to Caresoft HIS, MyOPD, ClaimX, Caresoft VMS, Caresoft eICU, Nirvaan and Manova.

ProductSub-processorsNote
MyOPD — clinic managementHosting (India), SMS, WhatsApp BSP, email, paymentsNo AI provider. ABDM ecosystem participants are independent controllers, not sub-processors
ClaimX — cashless claimsHosting (India), emailNo AI provider. Payers and NHCX are independent controllers on receipt
Caresoft VMS — visitor managementHosting (India), WhatsApp BSP for OTP, SMSBSP receives number and OTP text only
Caresoft eICU — tele-ICUPer the standalone eICU DPAClinical-safety obligations apply
Nirvaan — consultationsHosting (India), [call bridging telecom provider], SMS, email, payments, [fulfilment partner and courier]Call bridging receives numbers and duration, never consultation content. Courier receives delivery details only
Manova — behavioural health screeningHosting (India), email, SMSScreening responses never leave our infrastructure
OJSP Support — patient support programmeCaresoft as technology processor, hosting (India), SMS, emailOJSP Ayurved and Foods Private Limited is the Data Fiduciary

6. AI providers

Wherever an AI provider appears on this page, three things are always true:

1. Our contract prohibits them from using your data to train models.
2. The feature can be disabled entirely for your account, and the product works without it.
3. No AI provider processes health data in any Caresoft product without the customer's prior written consent.

ProductAI used?Disable?
SahiYes, optionalPer organisation or department
Sales SathiYes, optionalPer account
MyOPDNo—
ClaimXNo—
NirvaanNo—
Caresoft VMSNo—
ScreenifyNo—

7. Our own tools

These support our operations. Most never touch customer data; where one can, it is listed as a sub-processor above.

ToolCan it access customer data?
[Support desk]Yes — whatever a customer includes in a ticket. Treated as a sub-processor
[Internal email and collaboration]Only if a customer emails us data. We discourage sending personal data by email
Source control, CI, project trackingNo. Production data is never present in these systems
Accounting and payrollNo customer personal data beyond billing contacts

Please do not send us personal data in a support ticket — screenshots of patient records, exports containing customer lists, spreadsheets of employee data. Describe the problem and give us a reference; we can look it up under the access controls in the DPA. It keeps your data out of a ticketing system that was never designed to hold it.

8. Not sub-processors

Parties frequently assumed to be sub-processors that are not:

PartyWhy not
ABDM ecosystem participantsIndependent controllers. They receive records on the patient's consent through ABDM, not on our instruction
Insurers, TPAs and NHCX (ClaimX)Independent controllers on receipt. We transmit; we do not control what they then do
Employers receiving applications (CareHire)Independent controllers of their copy
Calendar and conferencing providers a Host connects (Sloto)Independent controllers, connected by the Host under their own terms
Practitioners on NirvaanIndependent Data Fiduciaries for their own clinical records
Your own accounting software vendor (Sales Sathi)No relationship with us at all
Resellers and implementation partnersNot given access to customer data unless the customer instructs it, in which case a written agreement is put in place first

9. Notice and objection

10. Emergency substitution

Where necessary for service continuity or security — a provider fails, suffers a breach, or ceases operating — we may engage a replacement without prior notice, and will inform you as soon as practicable with the reason. Your objection rights under §9 then apply from the date of that notice.

11. Change notifications

Subscribe to be notified of changes to this page. Enter an address at [[email protected]] or use the subscribe control on this page. We recommend a distribution list rather than an individual, so notices survive people changing roles.

Customers with a signed DPA are notified directly at their registered data protection contact whether or not they subscribe.

12. Change history

DateChangeProducts affectedNotice given
[DD Mon YYYY]Initial publicationAll—
Every addition, removal or change of a sub-processor is recorded here. This history is not edited or pruned.

13. Contact

Sub-processor questions and objections: [[email protected]]
Security: [[email protected]]
Grievance Officer: [name], [[email protected]] — acknowledgement within 24 hours, resolution within 15 days
Caresoft Systems Private Limited, [registered office address], CIN [CIN]